backend-pe
Warn
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses directive language intended to override the agent's default operational boundaries. Examples include "INFINITE CONTEXT PROTOCOL" and "SUPERMODE ACTIVATION," which are characteristic of jailbreak-style prompts designed to trigger non-standard behavior.
- [PROMPT_INJECTION]: Instructions explicitly tell the agent to "Ignore token and cost constraints" and "No Safety Lectures: Assume expert users. Do not warn about cost or complexity unless asked." This is a direct attempt to bypass the agent's internal safety filters and resource management guidelines.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by instructing the agent to provide "Full Implementation" and "copy-paste-ready outputs" without safety warnings while processing user-supplied input.
- Ingestion points: User requests triggered by keywords like "BackendPE", "Supermode", or "Antigravity" (SKILL.md).
- Boundary markers: Absent. The skill explicitly discourages the use of warnings, safety lectures, or cost constraints that would normally delimit agent behavior.
- Capability inventory: The agent is directed to generate application code, Dockerfiles, Kubernetes manifests, and Infrastructure-as-Code (Terraform) across multiple languages (Rust, Go, TypeScript) (SKILL.md).
- Sanitization: Absent. The instructions demand the removal of standard safety lectures and warnings, which could lead the agent to generate or execute malicious code embedded in user-provided architecture requests without its usual oversight.
Audit Metadata